VMTech
Discuss a project

cPanel fixes EmailTrack flaw enabling root server access

cPanel fixes EmailTrack flaw enabling root server access

cPanel releases fixes for root-level escalation flaw

cPanel has issued fixes for CVE-2026-67401, a vulnerability that could allow an authenticated hosting account with mail-related privileges to take control of an entire server. The company says every supported version of cPanel and WHM is affected. Its advisory, published on September 8, describes the issue as an SQL injection flaw in EmailTrack.

cPanel states that the vulnerable path can let an account holder create files of their choice on the server and subsequently execute code as the root user. In a shared-hosting environment, that changes the potential impact from compromise of an individual customer account to compromise of the host and its other tenants.

cPanel and WHM have distinct administrative scopes: customers manage a hosting account through cPanel, while providers administer the underlying machine through WHM as root. Root access can enable an attacker to access other hosting accounts, modify files and databases, create accounts, install malware, collect credentials and potentially move into customer networks.

Fixed builds and update options

cPanel listed fixed builds for the affected release lines: 11.110.0.143 for the 11.110 line, 11.134.0.55 for 11.134, 11.136.0.39 for 11.136, and 11.138.0.4 for 11.138. The fixed WP Squared build is 11.138.1.9.

  • 11.110: 11.110.0.143.
  • 11.134: 11.134.0.55.
  • 11.136: 11.136.0.39.
  • 11.138: 11.138.0.4.
  • WP Squared: 11.138.1.9.

Administrators can update through WHM at Home / cPanel / Upgrade to Latest Version. For command-line updates, cPanel instructs administrators to sign in as root and run /usr/local/cpanel/scripts/upcp --force.

Important unanswered questions

The advisory does not identify the exact cPanel feature or privilege needed by an account, nor does it explain how the stated SQL injection issue produces file creation and root-level execution. cPanel documentation describes an EmailTrack module for tracking email statistics, but the advisory does not confirm whether that module is the affected code.

cPanel also did not provide a mitigation for servers that cannot be updated immediately. It did not state whether applying the fixed build identifies or remediates a server compromised before patching, or how administrators should check for prior abuse. The advisory has no severity score.

As of September 9, no CVE Program record had been published for CVE-2026-67401, no public exploit code or exploitation report had appeared in searches, and the issue was absent from CISA's Known Exploited Vulnerabilities catalog released on September 8. Those observations do not rule out exploitation.

Operational implication for hosting providers

cPanel disclosed other root-impacting issues since late July, including a July database flaw and an August domain-parking flaw that also began with an ordinary hosting account. Hosting providers should prioritize the listed fixed builds, confirm the update across every managed server, and assess root-level activity and customer-account boundaries where patching was delayed.

#cpanel#websecurity#vulnerability#hosting
Open analytics
On the site 0 views
min read 3 09.09.2026
Instagram

cPanel fixes EmailTrack flaw enabling root server access

Open the post on Instagram ↗